LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Closed Thread
  Search this Thread
Old 09-07-2013, 03:17 PM   #1
cyb33r
LQ Newbie
 
Registered: Sep 2013
Posts: 3

Rep: Reputation: Disabled
Question Sniffing From Squid SSL


I created a Squid proxy and a self signed ssl, The SSL certificate on the server is a private cert linked to the ssl-bump feature. I am using tshark to dump the SSL traffic, but i can't sniffing with tshark. for example my tshark command is:
Code:
tshark -o "ssl.desegment_ssl_records: TRUE" -o "ssl.desegment_ssl_application_data: TRUE" -o "ssl.keys_list: 209.190.x.x,443,http,/etc/squid/ssl/file/squid.key" -o "ssl.debug_file: /tmp/.wireshark-log" -i eth0 -R "http.request.method==GET or http.request.method==POST"
I know the squid works (and i can sniffing all data from http), and i can see the log of https site in /var/log/squid/access.log but i can't sniff full data of https. i also know Squid becomes a man-in-the-middle in this scenario and make 2 ssl key One between the client and squid, the other between squid and the server. i can't sniff the data between the client and squid but i think i can sniffing data between server(me) and squid.
How can i sniff it? is there any alternative for tshark?
 
Old 09-07-2013, 09:22 PM   #2
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Moderator Response

Please re-read LQ Rules;
Quote:
Posts containing information about cracking, piracy, warez, fraud or any topic that could be damaging to either LinuxQuestions.org or any third party will be immediately removed
This thread is closed.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSL Certs on Squid citystriker Linux - Networking 2 01-11-2015 10:16 PM
needs anti sniffing tool for squid aliabbass Linux - Security 8 04-27-2011 02:52 PM
squid ssl gabsik Linux - Networking 6 05-15-2006 03:13 AM
SSL Tunnel Squid engnet Linux - Security 1 02-21-2006 07:02 AM
SSL Tuuneling in Squid manya Linux - Security 1 04-30-2005 04:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 12:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration